Data Processing Addendum
Version 1.0, 4 September 2026
This Addendum forms part of the agreement between Creativefuel Private Limited, Indore, Madhya Pradesh, India ("Processor", "we") and the customer organization that has subscribed to Speech ("Controller", "you"). Where this Addendum and the Terms of Service conflict on the processing of personal data, this Addendum governs.
To have this signed, write to support@creativefuel.io with your organization's legal name and address. We will return an executed copy. If your procurement requires your own paper instead, send it and we will review it.
1. Roles
You are the Controller of the personal data your people put into Speech. We are the Processor, and we process it only on your documented instructions, which are this Addendum, the agreement, and your use of the product's own settings. If we ever believe an instruction breaks applicable law, we will tell you rather than act on it.
2. What is processed
| Categories of data subject | Your employees, contractors and other people you give accounts to. |
|---|---|
| Categories of personal data | Email address; display name; audio a person dictates; the text transcribed from it; a short snippet of text immediately before the cursor; usage and diagnostic records; text a person selects when using Agent Mode; images generated at a person's request; bug reports a person sends, with any screenshot they attach. |
| Special categories | None are requested. Dictation is free-form speech, so a person may say anything; we do not scan for, index or infer special-category data, and Privacy Mode exists so that content need never be retained at all. |
| Nature and purpose | Transcribing speech to text, formatting it, returning it to the person's device, and operating and improving the service. |
| Duration | For the term of the agreement, and then as set out in section 8. |
3. Confidentiality
Access to your data is limited to the people who need it to run the service, each bound by confidentiality obligations that survive their engagement. Access to dictation CONTENT is further restricted: it is unreadable to us unless the individual has switched sharing on for their own account, and every content read is recorded in an append-only audit log.
4. Security measures
We maintain at least the following, which are described in plain language on the trust page:
- Encryption in transit: TLS 1.2 or higher for all traffic, with HSTS and a strict Content Security Policy.
- Encryption at rest for backups: AES-256 server side encryption, with a 60 day lifecycle and a least-privilege write-only upload identity.
- Network isolation: the database is not published to the internet and is reachable only from the application.
- Access control: administrative access is granted from a declared list, is separate from product privileges, and requires a second factor from an authenticator app.
- Audit logging: every administrative change and every cross-account read of dictation content, with actor, subject, time and source address, in an append-only log with no route that edits or deletes a row.
- Retention controls: Privacy Mode, which can be chosen per person, retains no audio and no transcript at all.
- Secure development: peer-reviewed changes, an automated test suite, dependency vulnerability scanning of everything shipped, and secret scanning of the repository history, all required before a change can merge.
- Backups: nightly, verified restorable, retained 60 days.
We may change these measures, but not in a way that materially reduces the level of protection.
5. Subprocessors
You authorise the subprocessors listed at speech.rupees.com/subprocessors.html, which forms Annex 2 of this Addendum and is the authoritative list. Each is bound by written terms no less protective than these, and we remain responsible for their performance.
We will give you at least 30 days notice before a new subprocessor begins processing your content. If you reasonably object on data protection grounds within that period and we cannot offer an alternative, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees.
6. International transfers
Your data is stored and processed in India (AWS ap-south-1, Mumbai). Two model providers used to transcribe or format a dictation operate in the United States, so content transits there for the seconds it takes to process and is not stored there.
Where you are established in the EEA, the United Kingdom or Switzerland and a transfer requires a lawful mechanism, the European Commission's Standard Contractual Clauses (Decision 2021/914, Module Two, controller to processor) are incorporated into this Addendum by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies. This Addendum's Annexes serve as the Clauses' Annexes: section 2 as Annex I.B, section 4 as Annex II, and section 5 as Annex III. The governing law and forum are those of the agreement to the extent the Clauses permit.
7. Assistance to you
- Data subject requests. The product answers most of them directly: a person can export or delete their own account and everything stored for it, and see their own history. Where you need our help with a request you cannot fulfil yourself, write to support@creativefuel.io and we will assist within a reasonable period and at no charge for reasonable volumes.
- Impact assessments. On request, we will give you the information you reasonably need for a data protection impact assessment or a consultation with a supervisory authority.
- Security incidents. We will notify you without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting your data, with what we know, what we are doing, and what we recommend, and we will keep you updated as we learn more.
8. Return and deletion
You may export your data at any time while the agreement is in force. On termination, and on your written request within 30 days of it, we will delete your organization's personal data. Absent a request, we delete it within 90 days of termination. Backups age out on their own 60 day cycle and are not restored except to recover the service.
9. Audit
We will answer reasonable security questionnaires and provide our then-current security documentation once a year, and more often after a security incident affecting your data. Where that is not sufficient for your regulator, we will agree a proportionate on-site or remote audit with reasonable notice, during business hours, under confidentiality, and at your cost.
We hold no SOC 2 report and no ISO/IEC 27001 certificate today. We say so here rather than let a questionnaire discover it.
10. Indian law
Where the Digital Personal Data Protection Act, 2023 applies, we act as a Data Processor to you as Data Fiduciary, process personal data only on your instructions, assist you with the obligations that Act places on you, and maintain the security safeguards in section 4. Our Grievance Officer's contact details are in the privacy policy, section 10.
11. Liability and term
Each party's liability under this Addendum is subject to the limitations and exclusions in the agreement. This Addendum takes effect when the agreement does and continues until we have deleted your organization's personal data under section 8.
Trust page · Subprocessors · Privacy policy · Terms
Speech by Creativefuel